SB2025061905 - Memory leak in Linux kernel hw hfi1 driver
Published: June 19, 2025 Updated: June 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-50134)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the setup_base_ctxt() function in drivers/infiniband/hw/hfi1/file_ops.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1750be1e9f18787cf717c24dbc5fa029fc372a22
- https://git.kernel.org/stable/c/2f90813f1c21c3d780585390af961bd17c8515ae
- https://git.kernel.org/stable/c/90ef48a718f88935d4af53d7dadd1ceafe103ce6
- https://git.kernel.org/stable/c/a85c7dd1edadcdeca24e603a6618153a3bcc81ca
- https://git.kernel.org/stable/c/a9055dfe437efae77e28e57205437c878a03ccb7
- https://git.kernel.org/stable/c/aa2a1df3a2c85f855af7d54466ac10bd48645d63
- https://git.kernel.org/stable/c/e25b828553aecb3185a8d8d0c4f9b4e133fb5db6
- https://git.kernel.org/stable/c/fc4de8009fd6c2ca51986c6757efa964040e7d02
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.291